WORK · I

LOCAL SOC & DETECTION ENGINEERING LAB · 1.0.0

SOCWERK

A compact analyst workspace that carries synthetic incidents from raw telemetry through explainable detections, evidence correlation, incident decisions, and professional reports.

01

INVESTIGATION WORKFLOW

FROM TELEMETRY TO DECISION

  1. 01INGESTRAW SECURITY TELEMETRY
  2. 02NORMALIZECONSISTENT EVENT MODEL
  3. 03DETECTFIELD-LEVEL MATCHES
  4. 04TRIAGECONTROLLED ALERT STATE
  5. 05CORRELATEENTITIES · TIME · ANCESTRY
  6. 06DECIDEFINDING · INCIDENT
  7. 07CONTAINSIMULATED ACTIONS
  8. 08REPORTMARKDOWN · JSON · HTML

02

ANALYST WORKSPACE

EVIDENCE BEFORE VERDICT

SOCWerk / CONVERGING SIGNALS
ADVANCED · 30–45 MIN
EVENT EXPLORERsource = sysmon and severity = high192 EVENTS
SELECTED EVENT

Command interpreter started PowerShell with encoded arguments

HIGH · MATCHED
cmd.exe → powershell.exe · usr-fin-610 · asset-ws-610
CONDITION 01
process_name equals powershell.exe
CONDITION 02
attributes.execution_style equals encoded
CORRELATION

Explicit scenario links, shared entities, process ancestry, and time proximity connect this event to adjacent evidence.

DETECTION MATCH

03

IMPLEMENTED SURFACE

AN INVESTIGATION, NOT A QUIZ

01

EXPLAINABLE DETECTIONS

Every match exposes the field, operator, expected value, and observed value that produced the alert.

02

PERSISTENT ANALYST STATE

Evidence, notes, hypotheses, findings, alert decisions, and incident decisions remain in SQLite.

03

PROTECTED ASSESSMENT

Expected outcomes stay on the backend until submission, followed by deterministic learning feedback.

04

BOUNDED QUERYING

A small read-only query language filters in-memory events without passing scenario input to SQL or an evaluator.

04

SCENARIO DOSSIER

CONVERGING SIGNALS

The advanced SOCWerk-native investigation asks the analyst to reconstruct a multi-stage compromise while separating hostile behavior from credible administrative and business lookalikes.

EVENTS
192
ALERTS
18
DETECTIONS
14
LEVEL
ADVANCED
TELEMETRY IN VIEW

EMAIL · OFFICE · SYSMON · POWERSHELL · WINDOWS SECURITY · VPN / MFA · DNS · PROXY · ENDPOINT · ZEEK

INCLUDED INVESTIGATIONS
  1. 01SUSPICIOUS LOGIN ACTIVITYIDENTITY · MFA · VPN
  2. 02PHISHING INVESTIGATIONEMAIL · BROWSER · ENDPOINT
  3. 03SUSPICIOUS POWERSHELLPROCESS · SCRIPT BLOCK · PROXY
  4. 04SUSPICIOUS FILE TRANSFERFILE · DNS · DLP

05

SYSTEM SHAPE

SMALL, LOCAL, EXPLICIT

ANALYST INTERFACESVELTEKITJSON / HTTP
DOMAIN / APIFASTAPIQUERY · DETECTION · CORRELATION
IMMUTABLE FACTSSCENARIO JSONREAD ONLY
ANALYST STATESQLITEEVIDENCE · DECISIONS

06

TRUST BOUNDARIES

DEFENSIVE BY CONSTRUCTION

  1. 01

    The lab does not scan networks, send phishing, generate payloads, execute scenario commands, or contact targets.

  2. 02

    All identities, domains, addresses, files, and infrastructure are synthetic; network indicators use reserved ranges and .example domains.

  3. 03

    Scenario packs are strict versioned JSON. They cannot load code or remote content, and their expected outcomes remain server-side before submission.

  4. 04

    Containment is a documented analyst decision only. It never performs an action against an external system.

SOURCE · ARCHITECTURE · THREAT MODEL

OPEN THE LAB. FOLLOW THE EVIDENCE.